SUSPICIOUS — 6836187.pdf
SUSPICIOUS — 6836187.pdf is a pdf sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (44/100). 2 of 50 detection engines flagged it.
Identification
- SHA-256:
69c02f83f5de547f5e5894ee13f136675755e681e6590f708bf5cf46abdd8e37 - SHA-1:
1940cc26d5c723f3953e55f73eb804b847d697cf - MD5:
01ff3a014ecffe90f1956944fb4acc27 - ssdeep:
1536:RGFm8ISUpWPxi7fRrrzNmkoQh+4c95/m0lx/4B:0FmwUzFrrzNoQhRcr/Nu - TLSH:
T15A34CFF352ABED4C2B85DB43AE690489254AD64C62335B9444DD7B7CC5BC2FCAF40822 - Submitted as: 6836187.pdf
- File type: pdf · Size: 55881 bytes
- Verdict: suspicious (44/100)
Detections (2 of 50 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
Why this verdict
The suspicious score of 44/100 is the fusion of 3 weighted signals:
- Embedded network infrastructure: https://trafffe.ru/wb?keyword=trouble%20in%20terrorist%20town%20rules, https://xajoxivanuxus.weebly.com/uploads/1/3/4/4/134432241/4331330.pdf, https://uploads.strikinglycdn.com/files/c102edb2-0af4-4d98-8ab8-437c71377955/86506076284.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://trafffe.ru/wb?keyword=trouble%20in%20terrorist%20town%20rules
- https://xajoxivanuxus.weebly.com/uploads/1/3/4/4/134432241/4331330.pdf
- https://uploads.strikinglycdn.com/files/c102edb2-0af4-4d98-8ab8-437c71377955/86506076284.pdf
- https://uploads.strikinglycdn.com/files/cc6a9f4a-5f5e-4e76-8443-f298a43bce7b/mobdro_download_apk_pc.pdf
- https://cdn-cms.f-static.net/uploads/4389085/normal_5f9e7d2c0604e.pdf
- https://cdn-cms.f-static.net/uploads/4403556/normal_5f98bdbfc502b.pdf
- https://uploads.strikinglycdn.com/files/81855ecd-a1a5-4117-b305-b7769fda8aa7/fluvanna_county_high_school_mascot.pdf
- https://uploads.strikinglycdn.com/files/ba468acd-0fd9-4cc6-bb8b-f3b0048bab89/vopeburaw.pdf
- https://cdn-cms.f-static.net/uploads/4379602/normal_5f9dcf91c6982.pdf
- https://cdn-cms.f-static.net/uploads/4454990/normal_5fa5f02956f51.pdf
- https://cdn-cms.f-static.net/uploads/4392862/normal_5fa7143e1f37c.pdf
- https://uploads.strikinglycdn.com/files/4b014c07-bbec-4f7f-8b6c-e3237aa1ac6f/86038722389.pdf
- https://cdn-cms.f-static.net/uploads/4369328/normal_5f880fc62bce1.pdf
- https://cdn-cms.f-static.net/uploads/4378620/normal_5f92c9d8df094.pdf
- https://vapijaroti.files.wordpress.com/2020/11/90950053825.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/pdf/1.3/
- http://ns.adobe.com/xap/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/rights/
Embedded domains
- trafffe.ru
- xajoxivanuxus.weebly.com
- uploads.strikinglycdn.com
- cdn-cms.f-static.net
- vapijaroti.files.wordpress.com
- www.w3.org
- purl.org
- ns.adobe.com
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report